DPDP Act vs GDPR: 12 Key Differences Every Indian Business Should Know

If your team has worked with Europe's GDPR, you have a head start on India's DPDP Act 2023 — but assuming they are the same law with different names is a costly mistake. The DPDP Act is shorter, stricter in places, more lenient in others, and structured around distinctly Indian concepts. Here are the twelve differences that matter most in practice.

1. Scope: digital data only

GDPR covers personal data in any form, including structured paper filing systems. The DPDP Act applies only to digital personal data — data collected digitally, or collected offline and later digitised. A paper register that is never scanned sits outside the Act; the moment it is digitised, it is in scope.

2. No categories of "sensitive" data

GDPR creates special categories (health, biometrics, religion, etc.) with stricter rules. The DPDP Act treats all personal data alike — there is no separate sensitive-data regime. The practical effect: obligations that GDPR reserves for special categories apply in India to every scrap of personal data you process.

3. Consent or "legitimate uses" — nothing else

GDPR offers six lawful bases, including the flexible "legitimate interests". The DPDP Act allows only two: consent, or one of the specifically listed legitimate uses (such as voluntary provision, employment purposes, medical emergencies and state functions). There is no general legitimate-interest basis to fall back on — if your processing doesn't fit a listed use, you need consent.

4. The age of a child: 18, not 16

GDPR sets the digital age of consent at 16 (member states may lower it to 13). India sets it at 18 — significantly expanding who counts as a child. Any organisation serving teenagers — education, gaming, edtech, social platforms — must obtain verifiable parental consent and must not track, behaviourally monitor or target advertising at minors.

5. Penalties: fixed caps, not turnover percentages

GDPR fines scale to 4% of global annual turnover. The DPDP Act sets fixed monetary ceilings — up to ₹250 crore for failing security safeguards, ₹200 crore for breach-notification failures and children's-data violations, ₹150 crore for SDF obligation breaches. For a small company, the Indian caps can be proportionally far harsher than 4% of turnover.

6. Breach notification: every affected individual, every time

Under GDPR, individuals are notified only when a breach poses high risk to them. The DPDP framework requires notifying the Data Protection Board and each affected data principal — without a risk threshold. Operationally this is a much heavier duty: you must be able to identify exactly whose data was affected, quickly.

7. Rights: a shorter list

The DPDP Act grants four rights — access, correction and erasure, grievance redressal, and nomination. GDPR rights with no DPDP equivalent include data portability, the right to object, and restrictions on automated decision-making. The right to nominate someone to exercise your rights after death or incapacity is uniquely Indian.

8. Duties of data principals

GDPR imposes obligations only on controllers and processors. The DPDP Act also imposes duties on individuals — not to impersonate others, not to suppress material information, not to file false complaints — with a penalty up to ₹10,000. No GDPR parallel exists.

9. Consent Managers

The DPDP Act creates a new institution: the Consent Manager, a Board-registered entity through which individuals can give, manage, review and withdraw consent across fiduciaries via an interoperable platform. GDPR has no equivalent — this is India borrowing from its account-aggregator playbook.

10. Cross-border transfers: blacklist, not whitelist

GDPR restricts transfers to countries lacking adequacy decisions (a whitelist approach). The DPDP Act permits transfers to any country except those specifically restricted by government notification (a blacklist approach) — more permissive by default, but subject to change at notification speed, and sectoral rules (like RBI data-localisation for payments) still apply on top.

11. DPO requirements

GDPR requires DPOs based on the nature of processing. In India, only Significant Data Fiduciaries must appoint a DPO — and that DPO must be based in India and report to the board of directors.

12. Notices in 22 languages

DPDP consent notices must give the data principal the option to read them in English or any of the 22 languages in the Eighth Schedule of the Constitution — a localisation duty GDPR never contemplated.

What this means for your compliance programme

If you are GDPR-compliant, roughly 60–70% of your machinery transfers: data mapping, security safeguards, breach playbooks, processor contracts. What needs Indian re-engineering: consent flows (no legitimate interests to lean on), children's data handling (18, verifiable parental consent), notice localisation, principal-facing breach notification, and Consent Manager readiness. A structured discovery and consent platform covers both regimes from one data inventory.

Frequently asked questions

Is GDPR compliance enough to be DPDP compliant?
No. GDPR compliance gives you a strong foundation — data mapping, security, breach response — but DPDP differs materially on consent (no legitimate-interest basis), children's data (under-18 with verifiable parental consent), notification of every affected individual after a breach, and notice languages. Each gap needs specific remediation.
Which law is stricter — DPDP or GDPR?
It depends on the area. GDPR is broader (all data formats, more rights, turnover-linked fines). DPDP is stricter on consent bases, the age of children (18 vs 16), and notifying every affected individual after a breach regardless of risk.
Does the DPDP Act apply to companies outside India?
Yes. Like GDPR, the DPDP Act has extraterritorial reach: it applies to processing outside India if it is connected to offering goods or services to individuals within India.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →

Ready to become DPDP compliant?

Get a personalised compliance assessment — free, no obligation.

Book a Free Assessment →